Encrypted/Encoded File

T1027.013

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use.

This type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files. Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.

The entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.

For example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a Phishing payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., User Execution).

Adversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until Command and Scripting Interpreter execution.

Detection rules1

Rules on DetectionCode tagged with T1027.013.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Windows Obfuscated Files or Information via RAR SFXAnomalyNULLSysmon EventID 11

Groups40

Show 16 more

Software195

Show 171 more

Campaigns13

Procedure examples248

Groups40

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used encoded and obfuscated files, images, and executables.

GroupAPT18

APT18 obfuscates strings in the payload.

GroupAPT19

APT19 used Base64 to obfuscate payloads.

GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

GroupAPT33

APT33 has used base64 to encode payloads.

GroupAPT39

APT39 has used malware to drop encrypted CAB files.

GroupBITTER

BITTER has used a RAR SFX dropper to deliver malware.

View all 40 groups examples

Software195

Used byProcedure example
MalwareANELLDR

ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data.

MalwareAria-body

Aria-body has used an encrypted configuration file for its loader.

MalwareAshTag

The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server.

MalwareAstaroth

Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys.

MalwareAttor

Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA.

MalwareAuditCred

AuditCred encrypts the configuration.

MalwareAvenger

Avenger has the ability to XOR encrypt files to be sent to C2.

MalwareBazar

Bazar has used XOR, RSA2, and RC4 encrypted files.

View all 195 software examples

Campaigns13

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis.

Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus encrypts its dynamic library files (.dll) using RC4, and when loaded only decrypts specific portions of the file using the key `3jB(2bsG#@c7`.

CampaignAPT41 DUST

APT41 DUST used encrypted payloads decrypted and executed in memory.

CampaignCutting Edge

During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary.

CampaignNight Dragon

During Night Dragon, threat actors used a DLL that included an XOR-encoded section.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors used Base64 to encode files with a custom key.

View all 13 campaigns examples

References2

  1. File obfuscation Open source
    Aspen Lindblom, Joseph Goodwin, and Chris Sheldon. (2021, July 19). Shlayer Malvertising Campaigns Still Using Flash Update Disguise. Retrieved March 29, 2024.
  2. SFX - Encrypted/Encoded File Open source
    Jai Minton. (2023, March 31). How Falcon OverWatch Investigates Malicious Self-Extracting Archives, Decoy Files and Their Hidden Payloads. Retrieved March 29, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.